CVE-2020-12009

A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior; ICONICS GenBroker32 v9.5 and prior.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
icscertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
VendorProductVersion
mitsubishielectricmc_works
𝑥
≤ 10.95.208.31
mitsubishielectricmc_works32
9.50.255.02
iconicsenergy_analytix
-
iconicsfacility_analytix
-
iconicsgenesis64
-
iconicshyper_historian
-
iconicsmobilehmi
-
iconicsquality_analytix
-
iconicssmart_energy_analytix
-
iconicsbizviz
-
iconicsgenesis32
-
𝑥
= Vulnerable software versions